CVE-2026-82078 is an unsafe dynamic class-loading vulnerability in the database connection utilities of PaperCut NG and PaperCut MF. Database driver classes are instantiated from configurable names without validation against an allowlist of approved drivers. An attacker able to manipulate the relevant configuration can cause arbitrary Java bytecode available on the application classpath to execute in the PaperCut server process's security context. The vulnerability is authenticated when exploited independently; chaining it with CVE-2026-81578 permits unauthenticated remote code execution. Affected versions include releases before 24.1.10, 25.0.0 through releases before 25.0.13, and 26.0.0 through releases before 26.0.5. Exploitation in the wild has been reported.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a small, single-file Python PaperCut security-assessment tool. The primary executable, papercut.py (about 54 KB), uses requests for HTTP(S) GET/POST probing, socket connections for TCP port prefiltering, and Rich for terminal output. It exposes commands for scan, fingerprint, CVE-specific checks, batch scanning, a local lab, an exploit mode, log detection, reporting, interactive use, and self-test. The scanner fingerprints reachable user-supplied targets for PaperCut, version information, Apache Tapestry indicators, and accessible administrative/database-configuration endpoints; it evaluates detected versions against hard-coded fixed-version thresholds. It suppresses TLS verification warnings and makes requests with a PaperCut-Security-Tool user agent. The repository also contains documentation, contribution/security policies, an MIT license, and a two-package requirements file. Although the project advertises a --force-gated remote exploit mode for authentication-bypass and unsafe-class-loading CVEs, the supplied documentation explicitly characterizes remote checks as indicator-based, limits concept demonstrations to loopback hosts, and says RCE/payload execution is not implemented. Accordingly, this is best characterized as a proof-of-concept assessment/exploit-simulation tool rather than a weaponized RCE implementation. No fixed external exploit-server URL, target IP, hard-coded port, filesystem target, or registry target is visible in the supplied code; remote scan targets are runtime user input.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
256 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PaperCut vulnerability discussed in a report about a pre-authentication remote code execution chain and patch bypasses. The excerpt does not identify this CVE's individual mechanism or map it to a specific watchTowr identifier. It references patches and bypasses but provides no fixed versions or confirmation that the bypasses have been resolved.
An authenticated remote code execution vulnerability involving attacker control over the JDBC connection URL and arbitrary connections. Exploited in the wild with CVE-2026-81578. Initially patched in 26.0.4, but researchers bypassed that fix; subsequent security.properties restrictions blocked the original execution route.
An unsafe dynamic class-loading vulnerability in PaperCut that can be chained with CVE-2026-81578's authentication bypass to achieve pre-authentication remote code execution.
An actively exploited PaperCut MF vulnerability that, when chained with CVE-2026-81578, permits unauthenticated settings modification and execution of malicious Java bytecode under the PaperCut server security context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.